INITIALIZING ·· 0%
Zero Trust Architecture
Security Layer

Protection

by design.

BYOK encryption. Physical isolation. Network controls. Compliance documentation. Security is not a feature you add — it is the foundation every deployment is built on.

BYOK Encryption
Physical Isolation
4-Eye Access
Audit Trail
20-Policy Insurance
Security Architecture
01 Encryption / 02 Physical / 03 Network / 04 Compliance
AES-256 GCM
BYOK · YOUR KEYS
KEY ESCROW OPTION
HSM BACKED
01
Encryption Layer

Your keys.
Your data.

Bring Your Own Key (BYOK) encryption across all storage and compute volumes. AES-256 GCM at rest, TLS 1.3 in transit. Verde Compute never holds, accesses, or stores your encryption keys — full cryptographic sovereignty by design.

BYOKKey Sovereignty
AES-256At Rest
TLS 1.3In Transit
Customer-managed keys — Verde holds zero copies
HSM-backed key storage available on request
Automated key rotation schedule — client-defined cadence
Optional key escrow with third-party notary for business continuity
DEDICATED POD
BIOMETRIC ACCESS
24/7 CCTV
4-EYE PROTOCOL
02
Physical Layer

Isolated cage.
Exclusive access.

Your deployment lives in a dedicated, physically isolated cage. No shared racks. No other tenants in your enclosure. Biometric access control, 24/7 CCTV with 90-day retention, mantrap entry, and strict 4-eye protocol for any hardware access.

DedicatedPhysical Cage
24/7CCTV Coverage
4-EyeAccess Protocol
Exclusive cage — zero co-location with other clients
Biometric + badge dual-factor entry at every perimeter
Mantrap anti-passback — no tailgating access
Chain of custody log for every hardware event
PRIVATE VLAN
DEDICATED UPLINK
ZERO TRUST FIREWALL
DDoS MITIGATION
03
Network Layer

Private network.
Your topology.

Dedicated VLAN with private IP space. No shared switching fabric with other tenants. Stateful firewall with zero-trust default-deny policy. DDoS mitigation at upstream peering level. Private dedicated uplinks to your corporate network available via MPLS or SD-WAN.

PrivateVLAN
Zero TrustFirewall
400GInfiniBand NDR
Isolated Layer-2 domain — no shared broadcast with other tenants
Default-deny stateful firewall with allowlist-only egress
MPLS or SD-WAN private link to your corporate network
BGP routing with your AS on request — full network sovereignty
SOC 2 TYPE II ROADMAP
ISO 27001 ROADMAP
GDPR CONTROLS
AUDIT DOCUMENTATION
04
Compliance Layer

Audit-ready
from day one.

Structured compliance documentation committed in every engagement. SOC 2 Type II audit scheduled post go-live, reports delivered on contractual schedule. ISO 27001 control mapping. GDPR data residency documentation. Formal security posture report delivered quarterly.

SOC 2Type II Roadmap
ISO 27001Control Map
GDPRResidency Docs
SOC 2 Type II audit — planned from Year 1, reports on contractual schedule following go-live
ISO 27001 control mapping document for your audit team
GDPR data residency and processing documentation
Quarterly security posture reports with executive summary
Scroll to advance
Security posture
documentation included.

Every engagement ships with a structured security posture package. No additional procurement, no consulting fees — compliance documentation is part of the base contract.

Certification
SOC 2 Type I & II
SOC 2 Type I targeted Q1 2027 (concurrent with first client go-live). SOC 2 Type II targeted Q3 2027 following 12-month observation period. Big 4 auditor engaged. Reports distributed to lender and qualified clients on contractual schedule.
Type I: Q1 2027 · Type II: Q3 2027
Standard
ISO 27001
Information security management system control mapping aligned to ISO 27001 Annex A. Control gap analysis available for your audit team.
Control Mapping Included
Regulation
GDPR
GDPR-aligned data residency documentation and Data Processing Agreement provided as standard. EU and UK deployment configurations discussed on a per-engagement basis.
EU & UK Deployment Configurable
Documentation
Audit Trail
Immutable event log of all physical and logical access events. Tamper-evident audit trail retained for 24 months minimum. Exportable in standard formats.
24-Month Retention
Reporting
Security Posture
Quarterly security posture reports delivered to your CISO or security team. Incident summary, vulnerability scan results, and remediation status.
Quarterly Delivery
Monitoring
24/7 SIEM
Security information and event management monitoring active around the clock. Alerting integrated with your security operations team on request.
Real-Time Alerts
Sovereign Protection
for every party.

Verde Compute engagements are structured around a 20-policy institutional insurance consortium — designed to protect all engaged parties across the full contract term. Business Interruption coverage extends for the full engagement duration. Insurance obligations are structured into the engagement financing. No separate procurement, no renewal management, no coverage gaps.

Financier
Lender’s Protection
Comprehensive institutional coverage committed at financial close. Financier protections are structural — not optional, not negotiated separately.
Committed at Close
Operator
Verde Coverage
Operational, liability, and continuity coverage maintained across the full engagement. Verde Compute carries the insurance burden — not the client.
Full Term Active
Client
Additional Insured
Clients are named Additional Insured parties on Verde's key policy layers — including Cyber Liability and Commercial General Liability. This means clients hold direct rights under the insurance contracts, not merely contractual claims against Verde. Coverage confirmed via Certificate of Insurance (COI) at MSA execution.
Direct Insurance Rights
Financier
Lender’s Protection
Comprehensive institutional coverage committed at financial close. Financier protections are structural — not optional, not negotiated separately.
Committed at Close
Operator
Verde Coverage
Operational, liability, and continuity coverage maintained across the full engagement. Verde Compute carries the insurance burden — not the client.
Full Term Active
Client
Counterparty-Zero
Client-side protection committed at MSA execution. Coverage structure, policy terms, and specific protections are documented in the Master Service Agreement.
MSA Documented

Specific coverage structure, policy terms, insurer identities, and protection commitments are disclosed under NDA and documented in the Master Service Agreement at engagement execution. All insurance descriptions on this page represent Verde Compute’s intended engagement framework subject to formal documentation.

What is covered
in every deployment.

No tiers, no add-ons. The following controls are included as standard in every Verde Compute engagement.

Encryption at Rest
AES-256 GCM — BYOK, customer-managed keys, HSM option
Encryption in Transit
TLS 1.3 — enforced on all management and data paths
Physical Access
Biometric + Badge — mantrap, 4-eye protocol, CCTV retention
Network Isolation
Private VLAN — dedicated Layer-2, zero shared switching fabric
Access Control
Zero Trust — default-deny, allowlist, MFA on all admin surfaces
Monitoring
24/7 SIEM — real-time event correlation, anomaly alerting
Incident Response
Priority SLA — 2-hour P1 response / <50ms P99 inference target — immediate detection-to-notification, formal RCA per engagement terms
Key Management
BYOK — Verde holds zero key material, rotation on client schedule
Client IP Ownership
Full Client Ownership — All model weights, training data, workload outputs, and intellectual property remain exclusively owned by the client. Confirmed in writing in the MSA
Export Controls
ITAR / EAR Compliant Framework — All compute remains on US soil. OFAC denied party screening at engagement onboarding
Confidential Computing
Hardware-Native TEE — NVIDIA Confidential Computing — model weights and inference data protected even from the infrastructure operator
Fire Suppression
Institutional-Grade — hardware-safe chemically inert suppression medium
Cyber Resilience
Multi-Layer Architecture — network segmentation, isolated recovery environment per deployment
Vendor Integrity
OEM-Only Sourcing — hardware traceability from manufacturer to deployment
20 policies.
Zero client exposure.

Verde's expanded insurance framework covers all three counterparties — client, financier, and Verde — across every material risk scenario. Every client is named as Additional Insured on Cyber, CGL, and Property layers — giving direct insurance rights, not just a contractual promise.

20Policy Layers
$15M+Cyber Liability
Full TermBI Indemnity Period
Engagement-SizedSurety Bond
AutomatedEmergency Cloud Activation
Emergency Cloud Compute — 6-Step Automatic Activation Protocol
01
<5 min
NOC detects primary cluster failure via automated monitoring
02
Rapid Activation
Verde activates pre-arranged cloud burst with pre-negotiated cloud provider
03
Seamless Migration
Client workloads migrate via pre-configured images. No client action required
04
Within 1 hr
Client notified with status update and restore timeline
05
2–4 weeks
Verde files BI claim. Cloud burst costs reimbursed via BI Extra Expense
06
Per HW SLA
Primary cluster restored. Client billed at standard rate throughout
✓ Zero charge to client ✓ Verde pays all cloud burst costs ✓ BI Extra Expense funded ✓ Pre-arranged cloud provider agreements
L1
Commercial Property — All-Risks

Physical hardware, racks, CDU, networking, storage. Factory → transit → DC. New-for-old replacement.

VerdeFinancier: 1st Loss Payee
L2 ★
Business Interruption — Full-Term Indemnity

Full engagement contract duration. Hardware re-delivery window fully within indemnity period. Includes Emergency Cloud Extra Expense sub-limit.

Verde RevenueClient: Service Continuity
L2a — NEW
BI Force Majeure Extension

Cascadia earthquake, regional grid failure >72h, pandemic disruption. Closes the Pacific Northwest seismic gap in standard BI.

All Three Parties
L2b — NEW
Contingent BI — Physical Supplier Failure

DC closure, hardware vendor facility disaster, logistics disruption. Verde revenue loss when a named physical supplier fails.

Verde
L2c — NEW
Cyber CBI / Systems Failure

NVIDIA software license failure, cloud provider outage affecting Emergency Cloud burst, SaaS supply chain failure.

Verde
L2d — NEW
Delay in Start-Up (DSU)

Pre-operations coverage if hardware delivery is delayed beyond agreed date. Covers DC MRC, staff salaries, NVIDIA license amortization for up to 6 months.

Financier: Debt ServiceVerde: Fixed Costs
L3
Extra Expense — Emergency Cloud Compute

Sub-coverage under BI L2. Funds cloud burst when primary cluster is unavailable. Client incurs zero charge.

Client: Zero-Cost Continuity
L4 — Upgraded
Cyber Liability — $15M + AI Model Recovery

Data breach, ransomware, DDoS, insider attacks. $5M AI model/dataset reconstruction sub-limit. Client is Additional Insured — direct rights.

Client: Additional Insured
L4b — NEW
Cyber-Physical Extension

Hacker manipulates CDU causing hardware destruction, malicious firmware destroying components. Closes the gap between Cyber and Property policies.

Verde
L5
Technology E&O — $10M

Verde's professional failures or negligence causing client financial loss or data exposure. Client IP exposure due to Verde operational error covered.

Client: Financial Recourse
L6
Commercial General Liability — $10M

Third-party bodily injury and property damage from Verde's operations. Client named as Additional Insured.

Client: Additional Insured
L7
D&O — $5M + Regulatory Defense

SPV and Verde Inc. management decisions. Regulatory defense sub-limit for export controls and state AI regulatory matters.

SPV GovernanceFinancier
L8
Workers' Comp & Employer's Liability

Oregon/Washington mandatory coverage for Verde Inc. full-time employees. Ensures workforce stability.

Verde Workforce
L8b — NEW
Employment Practices Liability (EPLI)

Wrongful termination, harassment, discrimination from Verde's W-2 employees. Defense costs covered.

Verde Inc.
L9
Umbrella / Excess Liability — $25M

Extended per-occurrence and aggregate limits above primary CGL, E&O, and employer liability.

Catastrophic Claim Extension
L10
Equipment Breakdown Insurance

CDU pumps, UPS modules, InfiniBand switches, PDUs — mechanical/electrical breakdown not covered by standard Property.

CDU · UPS · PDUFinancier: Named
L11 — Upgraded
Crime & Fidelity — $5M + Third-Party Extension

Covers crimes by Verde staff AND vendor/DC/contractor personnel with cage access. Standard Crime covers Verde employees only.

Verde Staff + Vendor Staff
L12
Environmental / Pollution Liability

CDU coolant spill, dielectric fluid, battery systems. EPA regulatory fines and cleanup costs from accidental coolant release.

Verde: EPA Compliance
L13
Trade Credit Insurance

80–90% of contracted monthly revenue recoverable if client fails to pay. Enables the non-recourse Take-or-Pay SPV lending structure.

Financier: Non-Recourse Enabler
L14
Surety Bond — Completion Bond & Performance Bond

Completion: if Verde fails to go live, insurer pays financier. Performance: if Verde fails full-term service, client receives direct surety payout — independent of Verde's solvency.

Completion: FinancierPerformance: Client
L15 — Upgraded
Key Person Insurance — CEO $5M + CTO $3M

Upgraded to $8M total. Sized for 36-month C-suite replacement cost in AI infrastructure.

Verde: Business Continuity
Transit (One-Time)
All-Risks Marine Cargo — Factory to DC

Hardware shipment from OEM factory to Pacific NW DC. All-Risks Marine — factory departure through Verde's written acceptance certificate.

Verde · Factory → DC
ScenarioPolicy Layer(s)Client ImpactClient Cost
Hardware failureProperty L1 + Equipment Breakdown L10New-for-old replacement; emergency cloud bridges downtimeZERO
Major incident incl. earthquakeBI 36mo L2 + Force Majeure L2a + Emergency Cloud L3Service continues on cloud; full engagement term protectedZERO
Cyber attack — breach / ransomwareCyber $15M L4 — Additional InsuredIR, forensics, AI model reconstruction funded; client directly coveredZERO
Hacker destroys hardware via CDUCyber-Physical L4b + Property L1Physical + cyber damage both covered — no policy gapZERO
Verde service negligenceTechnology E&O L5Financial compensation for losses caused by Verde's failureZERO (claim)
Vendor / contractor insider crimeCrime $5M + Third-Party Ext L11Verde staff AND vendor/contractor crimes coveredZERO
Verde fails to deliver (non-completion)Surety Bond — Completion Bond L14Financier compensated; project re-tenderedZERO
Verde cannot perform for full termSurety Bond — Performance Bond L14Client receives direct surety payout — independent of Verde solvencyZERO
Hardware delivery delayed 4–6 monthsDSU L2dVerde's fixed costs covered; Verde remains solvent; delivery resumesZERO
NVIDIA software license disruptionCyber CBI L2cRevenue loss covered while Verde resolves license issueZERO
Policy certificates and Additional Insured endorsements provided at NDA execution · Nation-state cyber attacks are excluded from all commercial cyber policies globally (Lloyd's mandate post-2020) — operational mitigation: NVIDIA Confidential Computing, Zero Trust NOC access, air-gap option for defense clients
Ready to Proceed?
Security review
available on request.

Schedule a technical security review with our team. NDA first, then full security posture documentation — compliance roadmap, SOC 2 commitment schedule, ISO controls, and penetration test planning.